Delving into the ways businesses could be targeted, best preventative practice for workforces, and how layers of protection combine to deliver effective cyber security for clients, SoGlos sits down with Jez Walton, technical director at System Force IT, to find out how Gloucestershire SMEs can work to prevent data breaches, and respond effectively when they happen.
What is a data breach, and how do they commonly occur?
A data breach is when information is accessed, disclosed, altered, lost or stolen by someone who should not have access to it. That might involve customer information, employee records, financial data, passwords or other commercially sensitive information.
There is sometimes a perception that a data breach means a sophisticated hacker has broken through a company's defences. In reality, many incidents begin with something much simpler. Phishing emails, stolen passwords, compromised Microsoft 365 accounts, malware, an employee clicking a malicious link, incorrectly configured systems, or information being accidentally sent to the wrong person can all result in a breach.
We also increasingly see attackers targeting the people within an organisation rather than trying to attack the technology directly. If an attacker can persuade somebody to reveal their credentials, approve a fraudulent request or click on something malicious, they may be able to bypass some of the technical barriers businesses have put in place.
That is why cyber security needs to combine good technology with good processes and regular staff awareness.
Why is it important for businesses, particularly SMEs, to prevent them?
The consequences of a data breach can go far beyond the immediate IT problem. There can be financial losses, business interruption, reputational damage and potentially regulatory consequences if personal information is involved. Businesses may also have to determine exactly what information has been compromised, inform affected customers and suppliers, and potentially report the incident to the Information Commissioner's Office.
For an SME, those consequences can be particularly difficult because smaller organisations generally don't have large internal IT, security, legal and communications teams available to deal with an incident.
There is also the issue of trust. Customers give businesses their information with an expectation that it will be protected. Once that trust has been damaged, rebuilding it can take considerably longer than recovering the affected computer systems.
The objective therefore isn't simply to stop cyberattacks. It is to reduce the likelihood of an incident occurring in the first place and ensure the business is resilient enough to respond and recover quickly if something does happen.
What can SMEs themselves do operationally to prevent data breaches?
There are several relatively straightforward measures that can significantly reduce risk.
Multi-factor authentication should be enabled wherever possible, particularly for email and cloud services. Businesses should also ensure systems and applications are patched regularly, devices are protected and monitored, important information is properly backed up, and employees only have access to the systems and data they genuinely need.
Password practices remain important too. Staff should use unique passwords and ideally a reputable password manager rather than reusing the same credentials across different services.
However, one of the most important measures is staff awareness. Employees need to feel comfortable questioning unusual emails, unexpected payment requests and suspicious login prompts. A five-minute phone call to verify something can potentially prevent a very expensive incident.
Businesses should also have an incident response plan. Knowing who to contact, what systems need to be isolated, who has the authority to make decisions and what actions should be taken during the first few hours of an incident can make an enormous difference.
Cyber Essentials is another very useful framework for SMEs because it establishes a practical baseline of security controls that every organisation should consider implementing.
The key is not to treat cyber security as something the IT department or IT provider deals with in isolation. Everyone in a business has a role to play.
How does System Force support its SME clients to prevent data breaches as a managed IT partner?
Our approach is based on layers of protection rather than relying on one security product.
For our managed clients, that includes areas such as multi-factor authentication, endpoint detection and response, security monitoring, vulnerability scanning, patch management, managed firewalls, Microsoft 365 security, secure backups, and ongoing monitoring of critical infrastructure.
An important part of this is ClearSignal, our own developing platform that brings together information from across a client's IT environment to give our team a clearer picture of their systems, devices and infrastructure.
The principle behind ClearSignal is simple. The earlier we can identify a potential problem, vulnerability, or unusual activity, the better the opportunity we have to investigate and address it before it becomes a serious business incident.
Alongside this, we continuously monitor and manage areas such as endpoints, firewalls, servers, internet connectivity and other critical infrastructure. We carry out regular patching and vulnerability scanning, and our managed backup systems don't simply check whether a backup completed. We also verify that protected systems can actually be recovered.
But technology is only part of the picture. As a managed IT partner, our role is also to help clients understand where their risks are, improve their processes and put appropriate controls in place.
System Force is UKAS ISO 27001 certified, so information security isn't simply something we provide as a product to customers. It forms part of how we operate our own business.
What should businesses do if a data breache does occur?
No organisation can realistically guarantee that it will never experience a cyber incident, which is why incident response and recovery are just as important as prevention.
When we're dealing with a suspected breach, the immediate priorities are to understand what has happened, contain the incident, and prevent further access or damage.
Depending on the circumstances, that might mean isolating affected devices, disabling compromised accounts, resetting credentials, reviewing security logs, identifying the initial point of compromise, and establishing what systems or information may have been accessed.
From there, we can help the client recover systems safely, restore services where necessary, and determine what additional security measures need to be implemented.
For our managed customers, we also have a 24/7 emergency escalation process for critical incidents. That ability to respond quickly is important because the first few hours of a cyber incident can have a significant bearing on its eventual impact.
Good backups and recovery planning are also critical. Having a backup is one thing. Knowing that it works, knowing how quickly you can restore from it, and having a plan for getting the business operational again are equally important.
Once the immediate incident has been contained, there should also be a proper review. The question shouldn't just be 'Are we back online?', it should also be 'How did this happen, what can we learn from it, and what do we need to change to prevent it happening again?'.
For us, that combination of prevention, detection, response, and recovery is what good cyber resilience looks like.
How can Gloucestershire SMEs find out more about preventing and managing data breaches?
One of the things we're keen to do at System Force is make cyber security easier for SMEs to understand. It can be a very technical subject, but business owners and their teams need practical advice they can actually use.
We regularly publish articles, guidance, and practical cyber security advice through the System Force blog and online resources. These cover subjects such as current cyber threats, Microsoft 365 security, phishing, passwords, backups, Cyber Essentials and practical steps businesses can take to improve their overall cyber resilience.
In September, we'll also be running a webinar focused specifically on incident response, looking at what businesses should do when a cyber incident or data breach occurs, how they can prepare beforehand, and what those crucial first actions should look like.
Preparation really matters. Trying to work out who to call, whether you should disconnect a system, where your backups are, or who has the authority to make decisions while an incident is unfolding is far from ideal. Having an incident response plan means those questions have already been considered.
Our September webinar will be a practical session designed to help businesses understand what an effective incident response plan looks like, what should happen during those crucial first stages of an incident, and how they can improve their own preparedness.
Gloucestershire SMEs can visit the System Force website and explore our blog and resources for practical guidance, join us for the September webinar, or get in touch with our team if they'd like to discuss their own cyber security arrangements.
Ultimately, cyber security isn't about trying to make an SME impenetrable. It's about making it much harder for an attacker to succeed, spotting problems quickly when they occur, and having the resilience and a plan to recover when something does go wrong.
To sign up for System Force's September webinar, visit systemforce.co.uk/webinar-sign-up – or for more information about its services, or to read its blog, head to systemforce.co.uk.
